tomcat-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject DO NOT REPLY [Bug 49000] Cookie parsing bug when an empty value has an equal sign on the end
Date Wed, 15 Dec 2010 19:28:25 GMT
https://issues.apache.org/bugzilla/show_bug.cgi?id=49000

--- Comment #11 from Henri Yandell <hyandell@amazon.com> 2010-12-15 14:28:21 EST ---
Yes, bob= is fine unless it's on the end of the line and then it's dropped (I
just doublechecked with some unit tests as it's been a while since I was
digging into this).

I think there are three options:

1) Spec purity. Drop 'key' and drop 'key='.
2) Closer to the spec. Drop 'key=', keep 'key'.
3) Backwards compat. Support 'key=' at end of line.

I think that, ideally, it would be a case of TC7 being #1, while Mark's
proposed ALLOW_NAME_ONLY_COOKIES feature would continue to support #3. I don't
think there's a value in dropping 'key=' and keeping 'key'.

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org


Mime
View raw message